lists.openwall.net   lists  /  announce  owl-users  owl-dev  john-users  john-dev  passwdqc-users  yescrypt  popa3d-users  /  oss-security  kernel-hardening  musl  sabotage  tlsify  passwords  /  crypt-dev  xvendor  /  Bugtraq  Full-Disclosure  linux-kernel  linux-netdev  linux-ext4  linux-hardening  linux-cve-announce  PHC 
Open Source and information security mailing list archives
 
Hash Suite for Android: free password hash cracker in your pocket
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Date: Tue, 5 Jul 2005 21:58:02 -0400 (EDT)
From: devnull@...ents.Montreal.QC.CA
To: bugtraq@...urityfocus.com
Subject: Re: /dev/random is probably not


[The From: address is a bitbucket, to deflect the autoresponder hordes.
Use the address in the signature to reach me.]

> Why anyone is using the old entropy based RNG at all on modern
> commodity hardware?

Who said anything about "modern commodity hardware"? :)

Not all machines running most of the OSes mentioned so far are lucky
enough to have hardware RNGs.  Certainly at most two of my machines do,
and likely only one.  (One is an Athlon 2600, the other a K6-2/500.
Everything else is much older.  Oh, wait, I have a P2 somewhere.  But
that's it.  All the rest are things like Sun SS20, Sun IPX, Mac IIci,
DEC AXPpci33.

Or do I just not deserve to have _any_ RNG for having the temerity to
run such old hardware? :)

/~\ The ASCII				der Mouse
\ / Ribbon Campaign
 X  Against HTML	       mouse@...ents.montreal.qc.ca
/ \ Email!	     7D C8 61 52 5D E7 2D 39  4E F1 31 3E E8 B3 27 4B


Powered by blists - more mailing lists

Powered by Openwall GNU/*/Linux Powered by OpenVZ